|
197791
|
7.0 |
HIGH
Local
|
php debian fedoraproject netapp oracle
|
php debian_linux fedora clustered_data_ontap communications_diameter_signaling_router
|
In PHP versions 7.3.x up to and including 7.3.31, 7.4.x below 7.4.25 and 8.0.x below 8.0.12, when running PHP FPM SAPI with main FPM daemon process running as root and child worker processes running …
|
CWE-787
Out-of-bounds Write
|
CVE-2021-21703
|
2024-11-21 14:48 |
2021-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197792
|
9.8 |
CRITICAL
Network
|
zte
|
mf971r_firmware
|
ZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to execute arbitrary code.
|
CWE-787
Out-of-bounds Write
|
CVE-2021-21749
|
2024-11-21 14:48 |
2021-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197793
|
9.8 |
CRITICAL
Network
|
zte
|
mf971r_firmware
|
ZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to execute arbitrary code.
|
CWE-787
Out-of-bounds Write
|
CVE-2021-21748
|
2024-11-21 14:48 |
2021-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197794
|
4.3 |
MEDIUM
Network
|
zte
|
mf971r_firmware
|
ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification, an attackercould use this vulnerability to perform illegal authorization operations by sending a reque…
|
CWE-352
Origin Validation Error
|
CVE-2021-21745
|
2024-11-21 14:48 |
2021-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197795
|
7.5 |
HIGH
Network
|
zte
|
mf971r_firmware
|
ZTE MF971R product has a configuration file control vulnerability. An attacker could use this vulnerability to modify the configuration parameters of the device, causing some security functions of th…
|
NVD-CWE-noinfo
|
CVE-2021-21744
|
2024-11-21 14:48 |
2021-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197796
|
4.3 |
MEDIUM
Network
|
zte
|
mf971r_firmware
|
ZTE MF971R product has a CRLF injection vulnerability. An attacker could exploit the vulnerability to modify the HTTP response header information through a specially crafted HTTP request.
|
CWE-74
Injection
|
CVE-2021-21743
|
2024-11-21 14:48 |
2021-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197797
|
6.1 |
MEDIUM
Network
|
zte
|
mf971r_firmware
|
ZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie information.
|
CWE-79
Cross-site Scripting
|
CVE-2021-21747
|
2024-11-21 14:48 |
2021-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197798
|
6.1 |
MEDIUM
Network
|
zte
|
mf971r_firmware
|
ZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie information.
|
CWE-79
Cross-site Scripting
|
CVE-2021-21746
|
2024-11-21 14:48 |
2021-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197799
|
7.8 |
HIGH
Local
|
gonitro
|
nitro_pro
|
An exploitable double-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a reference to a timeout object to be stored in two different…
|
CWE-415
Double Free
|
CVE-2021-21797
|
2024-11-21 14:48 |
2021-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197800
|
7.8 |
HIGH
Local
|
gonitro
|
nitro_pro
|
An exploitable use-after-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause an object containing the path to a document to be destroye…
|
CWE-416
Use After Free
|
CVE-2021-21796
|
2024-11-21 14:48 |
2021-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|